CVE-2026-69296
massUse-after-free privilege elevation in Windows Device Association Service
A use-after-free memory-safety flaw (CWE-416) affects the Windows Device Association Service, the built-in Windows service that handles pairing and association between the system and wired or wireless devices. Per Microsoft's rating, a credentialed, low-privilege (authorized) attacker can trigger it over the network, but only with high attack complexity, i.e., a timing/race window typical of use-after-free bugs, and with some user interaction required. Successful exploitation elevates the attacker's privileges with high impact to confidentiality, integrity, and availability, amounting to effective compromise of the target system at elevated privileges. The available data does not specify affected Windows version ranges; any Windows deployment running the Device Association Service is potentially affected, and remediation is delivered through Microsoft security updates. No exploitation is currently known: the flaw is not in CISA's KEV, no public proof-of-concept exists, and EPSS estimates only a 0.5% chance of exploitation in the next 30 days (43rd percentile).
What to do: Install Microsoft's security update addressing CVE-2026-69296 via Windows Update, WSUS, or your endpoint-management tooling as soon as it is available, prioritizing endpoints where low-privileged users could be induced into the required interaction. In the meantime, protect low-privileged credentials and limit untrusted network reachability to Windows hosts, since the attack requires authenticated access. Avoid disabling the Device Association Service as a workaround unless device pairing functionality is not needed.
| Microsoft Windows (Device Association Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.